CVE-2025-22862EPSS p14.8%

CVE-2025-22862CVE-2025-22862

fortinet / fortios

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.

Scoring

CVSS 6.7 ()
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS0.24% probability of exploitation · percentile 14.8% · 2026-08-03T12:00:16Z
Last modified2026-06-09

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
CVE
Fortinet Multiple Products Authentication Bypass Vulnerability
CVE
CVE-2026-44277
CVE
CVE-2025-53744
CVE
CVE-2025-53847
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.